EIP-2026-106301
PRE-CVECuteNews 1.4.1 - 'function.php' Local File Inclusion
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-106301. PoCs published by Hamid Ebadi.
AI-analyzed exploit summary This exploit targets CuteNews 1.4.1 and below, leveraging a path traversal vulnerability to read arbitrary files, specifically the users.db.php file containing hashed passwords. The script sends a crafted HTTP POST request to the target server, bypassing authentication to retrieve sensitive data.
Description
CuteNews 1.4.1 - 'function.php' Local File Inclusion
Exploits (1)
This exploit targets CuteNews 1.4.1 and below, leveraging a path traversal vulnerability to read arbitrary files, specifically the users.db.php file containing hashed passwords. The script sends a crafted HTTP POST request to the target server, bypassing authentication to retrieve sensitive data.